{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sharepoint-server-subscription-edition--16.0.19725.20522/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:subscription:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-65660"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SharePoint Enterprise Server 2016 (\u003c 16.0.5565.1001)","SharePoint Server 2019 (\u003c 16.0.10417.20198)","SharePoint Server Subscription Edition (\u003c 16.0.19725.20522)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","exploitation","sharepoint"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Canadian Centre for Cyber Security has confirmed active exploitation of CVE-2026-65660, a code injection vulnerability (CWE-94) affecting Microsoft SharePoint Server. The flaw permits an authenticated attacker to achieve arbitrary code execution on vulnerable instances. Crucially, when chained with other SharePoint vulnerabilities, attackers can reach pre-authentication remote code execution (RCE) on servers that allow anonymous access. This poses a severe risk to organizations running legacy or unpatched SharePoint deployments. Microsoft SharePoint Enterprise Server 2016 and Server 2019 reached end-of-life on July 15, 2026, and remain highly susceptible. Defenders must prioritize upgrading to the specified fixed versions to remediate the vulnerability and mitigate the risk of ongoing exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Microsoft SharePoint instances.\u003c/li\u003e\n\u003cli\u003eIf anonymous access is enabled, the attacker chains existing auxiliary vulnerabilities to bypass initial authentication.\u003c/li\u003e\n\u003cli\u003eAttacker targets the specific code injection vector defined by CVE-2026-65660.\u003c/li\u003e\n\u003cli\u003eThe malicious request triggers the underlying vulnerability, allowing for code execution within the SharePoint application context.\u003c/li\u003e\n\u003cli\u003eAttacker executes arbitrary commands, potentially deploying a web shell to maintain persistence (e.g., via T1505.003).\u003c/li\u003e\n\u003cli\u003eAttacker leverages the elevated application context to perform further privilege escalation or move laterally within the server environment.\u003c/li\u003e\n\u003cli\u003eAttacker achieves the final objective, which may include data exfiltration or internal network reconnaissance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain full code execution on affected SharePoint servers. This can lead to total system compromise, unauthorized access to sensitive internal data, and the establishment of persistent backdoors within the organization's network. Given that many SharePoint instances store critical business and enterprise data, the impact of a successful breach is significant. Organizations running EOL versions (2016 and 2019) are at a particularly elevated risk, as they no longer receive standard support and may lack defense-in-depth protections.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all SharePoint instances to the fixed versions listed below. Enable Antimalware Scan Interface (AMSI) integration for SharePoint web applications and set the scan mode to 'Full' to improve detection of malicious payloads. Restrict access to management interfaces like SharePoint Central Administration and ensure all internet-facing instances are shielded from unnecessary exposure. Monitor IIS and SharePoint logs for anomalous administrative behavior, unauthorized web part modifications, and unexpected deserialization activity that may signal exploitation.\u003c/p\u003e\n","date_modified":"2026-09-24T19:51:47Z","date_published":"2026-09-24T19:51:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sharepoint-rce/","summary":"Authenticated attackers are actively exploiting CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server, to execute arbitrary code, with potential for pre-authentication RCE when chained with other flaws.","title":"Active Exploitation of Code Injection Vulnerability in Microsoft SharePoint Server","url":"https://feed.craftedsignal.io/briefs/2026-09-sharepoint-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - SharePoint Server Subscription Edition (\u003c 16.0.19725.20522)","version":"https://jsonfeed.org/version/1.1"}